It's more than that even - given that a high portion of the code being run now is using virtual machines, a lot of that protection is redundant. If all code is run inside VMs and zero 'native' code is allowed, then you could run without needing protection rings, system call overhead, memory mapping, etc - which in theory could more than make up for the virtual machine overhead.
This was being explored with Microsoft's Singularity and Midori projects but seems to be a dormant idea.
A fun talk on this idea with JavaScript: https://www.destroyallsoftware.com/talks/the-birth-and-death...